graphql-threat-matrix

GraphQL vulnerability checker

A framework to help identify security gaps in GraphQL APIs by analyzing implementation differences and vulnerabilities.

GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations

GitHub

297 stars
9 watching
28 forks
last commit: about 1 year ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

Repository Description Stars
nicholasaleks/crackql A utility for automatically generating and sending multiple payload variations to test GraphQL APIs' strength against common attacks such as brute-forcing, password spraying, and fuzzing. 318
davinerd/gql_intruder A tool to assess vulnerabilities in GraphQL endpoints by simulating attacks. 13
gsmith257-cyber/graphcrawler Automated testing toolkit for GraphQL APIs 305
omar2535/graphqler A tool to dynamically test GraphQL APIs with a focus on context awareness 129
doyensec/inql A tool for testing GraphQL APIs with vulnerability detection and customizable scans. 1,554
omar-dulaimi/graphql-shield-generator Automatically generates a shield to restrict access to sensitive data in GraphQL schemas. 9
nerdsupremacist/graphaello A tool that enables writing data-driven and type-safe applications in SwiftUI using GraphQL 492
swisskyrepo/graphqlmap A tool for automating interaction with GraphQL endpoints for pentesting and vulnerability assessment. 1,408
dolevf/damn-vulnerable-graphql-application An intentionally vulnerable GraphQL implementation to test security 1,518
incetarik/nestjs-graphql-zod A library that provides a way to work with GraphQL objects using Zod validation objects. 86
btkelly/gandalf A tool to manage application updates and security by detecting vulnerabilities and blocking older versions 282
denniskniep/gqlraider A Burp Suite extension for inspecting and manipulating GraphQL queries 21
dolevf/graphw00f A tool to identify and analyze the underlying technology behind a GraphQL endpoint. 587
dolevf/graphql-cop A tool to scan GraphQL APIs for common security vulnerabilities and report potential issues 401
graphql-rust/graphql-parser A tool for parsing and formatting GraphQL query and schema definitions in Rust. 355